© 2025-2026 PySpect
First version without a known vulnerability: 2026.6.0
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
Fixed in: 2026.6.0
Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
Fixed in: 2026.6.0
Home Assistant has stored XSS in history-graphs
Fixed in: 2026.01
Home Assistant has stored XSS in Map-card through malicious device name
Fixed in: 2026.01
Home Assistant Core before is vulnerable to Directory Traversal
Fixed in: 2025.8.0
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
Fixed in: 2025.10.2
Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
Fixed in: 2024.1.6
User accounts disclosed to unauthenticated actors on the LAN
Fixed in: 2023.12.3
Home Assistant vulnerable to account takeover via auth_callback login
Fixed in: 2023.9.0
Home Assistant information disclosure vulnerability
Fixed in: 0.67.0